[ad_1]
Crypto exchange Liquid, one of Japan’s most popular exchanges, is now short of $ 97 million in total assets after a cyberattack that pulled funds directly from the wallets of some of its clients.
In 2020, Japan amended its Payment Services Act (PSA) and Financial Instruments and Exchanges Act (FIEA) to put in place certain cryptocurrency regulations in the country, primarily requiring that exchanges cryptographic funds separate users’ money from their own internal finances. This typically means using offline “cold wallets” or outsourcing this function to a third party, but some Japanese crypto exchanges maintain “hot wallets” and meet regulatory requirements by holding the same type and amount of all user assets so that refunds can be issued directly if needed. This is the option chosen by Liquid, and the company has suspended deposits and withdrawals of assets to address the situation.
One month for major crypto exchange heists
Liquid lost $ 45 million in Ethereum in the cyber attack, in addition to around $ 52 million split between Bitcoin, XRP, and a variety of stablecoins (like Tether). Liquid did not confirm the total amount lost in the attack, with the estimate of $ 97 million coming from outside blockchain analytics firm Elliptic.
Liquid’s tweets indicate that the cryptocurrency exchange is still investigating the situation and has yet to release information on how the attack was carried out. In addition to temporarily suspending deposits and withdrawals, Liquid has moved all existing funds to more secure offline cold wallets.
The situation is shaping up to be a major problem for the popular cryptocurrency exchange, as security researchers have observed that stolen Ethereum tokens are converted to Ether through decentralized exchanges to escape the possibility of freezing. The situation is reminiscent of the very recent breach of the decentralized financial platform Poly Network, which was hit for $ 610 million (making it, at least initially, the biggest cryptocurrency heist in history) . However, it seems unlikely that this story would unfold the same way. The Poly Network hacker (known as “White Hat”) began repaying funds within the day, claiming he was only demonstrating a vulnerability and never intended to keep the money. Poly Network released an update Monday morning saying it had recovered all of those funds. The Liquid attack happened just before the weekend, and so far there is no indication who could be the culprit or that they intend to return tokens.
A still unknown liquid cyberattack vector
Liquid says he’s working with outside companies to track the movement of stolen assets and freeze them where possible. It appears that all deposits and withdrawals, except those involving fiat currencies, will remain frozen until the fallout from the cyberattack is resolved. The company confirmed on Monday that around $ 16 million in ERC-20 assets have been successfully frozen.
The only crumb of substantial information that the crypto exchange has released so far is that cyber attackers were targeting specific wallets, but taking a wide variety (around 69) of coin types. A blog post in Japanese revealed that the MPC wallets used by Singapore-based subsidiary Quoine were the ones under attack. This is a particularly interesting point because MPC (Multiparty Computing) is a relatively new technology considered to be highly secure because it runs protocols in chunks managed by several parties so that no outside observer can ever have access to all the necessary parts. . There is strong interest in MPC beyond the cryptocurrency space; traditional banks are examining it, as are some countries looking for ideas for online voting systems. Major financial players who recently acquired MPC companies include PayPal and BNY Mellon.
John Callahan, CTO of Veridium, provided additional information on the types of crypto exchange wallets that were allegedly attacked: Regarding the Japan Liquid Global Exchange hot wallet heist: presumably these are custodial portfolios managed on the ‘exchange for customers. Further details will be forthcoming, but I’m wondering if private keys are stored in the clear (or with a common key for all clients) instead of through a vaulted KMS with biometric consent to prevent hot wallet hijacking even on the server ? By blacklisting the addresses receiving the stolen funds, it will help trace transfers, but could get very complicated quickly as they hunt transfers around the world and across channels.
The #crypto liquid exchange lost $ 45 million in Ethereum in the #cyberattack in addition to around $ 52 million split between Bitcoin, XRP, and a variety of stablecoins. Liquid did not confirm the total amount lost in the attack. #cybersecurity #respectdataClick to Tweet
While this is pure speculation at this point, the current cyberattack on Liquid’s crypto exchange may be linked to the one that was successfully executed in November. This cyberattack saw an unknown party breach employee email accounts and then move to the internal network. No funds have gone missing, but it is possible that the attacker stumbled upon confidential information about the security of the crypto exchange. If so, the attacker probably wouldn’t have compromised the MPC protocol, but instead found a way to bypass it entirely within Liquid’s internal network.
|
Sources 2/ https://www.cpomagazine.com/cyber-security/cyber-attack-on-crypto-exchange-liquid-results-in-loss-of-97-million-in-ethereum-tokens-and-other-assets/ The mention sources can contact us to remove/changing this article |
[ad_2]